{
  "markdown": "# Verificate MCP — your vibe-coded MVP, all the way to production\r\n\n[![Verificate Gate](https://img.shields.io/badge/gated%20by-Verificate%20Gate-2ea44f?logo=shield&logoColor=white)](https://github.com/VerificateAI/verificate-gate-action)\n\n\r\n<p align=\"center\">\r\n  <img src=\"assets/verificate-demo.gif\" alt=\"Verificate MCP rejecting AI-written payment code at 70, then approving the fix at 91.2 — real output from the live server\" width=\"840\">\r\n</p>\r\n\r\n<p align=\"center\"><em>Real output from the live server: 12 lines of AI-written payment code — rejected, fixed, approved, in seconds.</em></p>\r\n\r\n**You vibe-coded the demo. This ships it.** Between a working demo and a launched product used to stand an experienced CTO and a senior dev team — the people who catch the mock refund path, the invented SDK call, the loop that dies at real traffic. Verificate MCP is that review team as an MCP server: **17 deterministic reality gates with veto power**, fused with a **frontier-model enterprise review** (ISO/IEC 25010: performance, scalability, reliability), run on every AI-written change before it reaches your codebase. The AI writes; the gate holds the bar; you ship. Hosted, zero-install, binary verdict in seconds — in Claude Code, Cursor, Windsurf or any MCP client.\r\n\r\n**Not another linter wrapper.** The code-quality shelf on every MCP directory is two things: scanners (ESLint, Semgrep and SonarQube bridges — deterministic rules, no judgment) and prompt relays that pipe your repo to your own LLM key (self-review with extra steps). Verificate is neither: the gates hold veto power that no model output can override.\r\n\r\n[![License: MIT](https://img.shields.io/badge/License-MIT-8CCB43.svg)](LICENSE)\r\n[![Official MCP Registry](https://img.shields.io/badge/MCP_Registry-ai.verificate%2Fmcp-blue)](https://registry.modelcontextprotocol.io/v0/servers?search=verificate)\r\n[![Docker MCP Registry](https://img.shields.io/badge/Docker_MCP-PR_%234551-2496ED)](https://github.com/docker/mcp-registry/pull/4551)\n[![MCP Market](https://img.shields.io/badge/MCP_Market-verificate-8A2BE2)](https://mcpmarket.com/server/verificate)\r\n[![Free trial](https://img.shields.io/badge/Free_trial-30_days,_no_card-8CCB43)](https://verificate.ai/auth/signup)\r\n\r\nYour coding assistant writes a mock and calls it done. It invents an SDK call that doesn't exist. It ships an N+1 loop that passes every test and dies under load. Verificate MCP runs the deep review pass on every AI output — deterministic reality gates first (any one can veto), then an enterprise-grade review scores what survives — **before the code reaches your codebase**.\r\n\r\n## A real rejection (verbatim)\r\n\r\n12 plausible lines of AI-written payment code were sent through the production gateway. Verdict: **REJECTED — score 30.8/100, vetoed by `code_reality_gate`**, with findings including:\r\n\r\n> *\"N+1 synchronous API calls … For 100 items, this results in 100 sequential HTTP roundtrips, taking ~10–20 seconds and blocking the event loop/worker thread … will trigger Stripe rate limiting (100 req/sec limit).\"*\r\n> *\"`stripe.Inventory` is not a valid Stripe SDK resource.\"*\r\n> *\"Floating-point representation issues lead to rounding errors in financial transactions; Stripe API requires integer cents.\"*\r\n\r\nEach of those is an afternoon of production debugging, caught in seconds.\r\n\r\n## Measured — vs. asking the model to review its own code\n\nA frontier model asked *\"is this OK to merge?\"* in a natural workflow missed reward-gaming (a test\nthat only does `assert True`) and a hallucinated API (`stripe.Refund.create_partial`) in **0 of 6\nruns each**. Verificate's gate caught both **6 of 6 — deterministically**, with **0 false positives**\non clean code.\n\n| Adversarial case | LLM review alone | **Verificate gate** |\n|---|---|---|\n| Reward-gaming (`assert True` test) | 0 / 6 | **6 / 6** |\n| Hallucinated API (nonexistent SDK call) | 0 / 6 | **6 / 6** |\n\n**Battle-tested:** 2,581 audited validations over 5 weeks (66 rejected, 270 flagged unfit),\nincluding guarding the write-path of a **21M-entity source-cited knowledge base** (98.6% cited,\n100% licensed across 268 sources). Reproduce it: [`scripts/`](scripts/) · full write-up: [`COMPARISON.md`](COMPARISON.md).\n\n## Tools\r\n\r\nEach tool has one job — two gates that return verdicts, one advisor that doesn't, one generator:\r\n\r\n| Tool | Job | Returns |\r\n|---|---|---|\r\n| `validate_ai_output` | **The merge gate for AI-written code.** Deterministic reality gates (mock/placeholder veto, gaming & bypass detection, invented-API checks) run first and can't be overridden; ISO/IEC 25010 review scores what survives. | Binary **approve/reject** verdict + severity-ranked findings |\r\n| `validate_plan` | **The gate for plans and designs**, before any code exists — completeness, feasibility, scalability implications, risk. The cheapest place to catch a bad design. | Binary **approve/reject** verdict + findings |\r\n| `analyze_code` | **Advisory deep-dive** on existing code — hot paths, rate-limit math, failure modes, tech debt. Use it to understand a rejection or review inherited code. | Scores + findings, deliberately **no verdict** |\r\n| `generate_code` | **Generate + gate in one step** — the LLM writes it, the same protection engine vets it before you see it. | Gated code (no placeholders, no invented APIs) |\r\n\r\n### Beyond tools\r\n\r\nThe server also ships **prompts** and **resources** for a richer client experience:\r\n\r\n- Prompts `gate_my_changes` / `review_my_plan` — one-click workflows that loop validate → fix → re-validate until approved.\r\n- Resources `verificate://gates` (what each of the 17 deterministic gates watches for) and `verificate://example-verdict` (a verbatim production rejection).\r\n\r\n## Quick start — no signup, no token, 30 seconds\r\n\r\nEvery machine gets **25 free validations** — no account, no card, no key. Add the URL and go:\r\n\r\n**Claude Code**\r\n\r\n```bash\r\nclaude mcp add --transport http verificate https://mcp.verificate.ai/mcp\r\n```\r\n\r\n**Cursor / VS Code — one-click install:**\r\n\r\n[![Add Verificate to Cursor](https://img.shields.io/badge/Cursor-Add_Verificate_%E2%80%94_25_free_calls-111111?labelColor=8CCB43)](https://cursor.com/en/install-mcp?name=verificate&config=eyJ1cmwiOiJodHRwczovL21jcC52ZXJpZmljYXRlLmFpL21jcCJ9)\r\n[![Add to VS Code](https://img.shields.io/badge/VS_Code-Add_Verificate-0078d7?labelColor=8CCB43)](https://vscode.dev/redirect/mcp/install?name=verificate&config=%7B%22type%22%3A%22http%22%2C%22url%22%3A%22https%3A%2F%2Fmcp.verificate.ai%2Fmcp%22%7D)\r\n[![Add to VS Code Insiders](https://img.shields.io/badge/VS_Code_Insiders-Add_Verificate-24bfa5?labelColor=8CCB43)](https://insiders.vscode.dev/redirect/mcp/install?name=verificate&config=%7B%22type%22%3A%22http%22%2C%22url%22%3A%22https%3A%2F%2Fmcp.verificate.ai%2Fmcp%22%7D)\r\n\r\n*LM Studio and Goose one-click buttons are at <https://verificate.ai/mcp> (GitHub strips their custom-protocol links).*\r\n\r\n**Windsurf / any MCP client (JSON)**\r\n\r\n```json\r\n{\r\n  \"mcpServers\": {\r\n    \"verificate\": {\r\n      \"url\": \"https://mcp.verificate.ai/mcp\",\r\n      \"transport\": \"http\"\r\n    }\r\n  }\r\n}\r\n```\r\n\r\nCursor: `~/.cursor/mcp.json`. Windsurf: `~/.codeium/windsurf/mcp_config.json`.\r\n\r\nThen ask your assistant to *\"validate this function with verificate\"* — a structured verdict comes back in seconds, and every free-tier response shows how many validations you have left and what the gate has caught for you.\r\n\r\n### Keep going after the free 25\r\n\r\nSign up at <https://verificate.ai/auth/signup> (30-day trial, no card — then $30/mo) and add your token to the same config:\r\n\r\n```bash\r\nclaude mcp add --transport http verificate \\\r\n  https://mcp.verificate.ai/mcp \\\r\n  --header \"Authorization: Bearer YOUR_TRIAL_TOKEN\"\r\n```\r\n\r\nor in the JSON config add `\"headers\": { \"Authorization\": \"Bearer YOUR_TRIAL_TOKEN\" }`.\r\n\r\n## Make gating the default\r\n\r\nTools an agent *may* call are tools it will skip under pressure. Add a standing rule (Claude Code: `CLAUDE.md`; Cursor: a rule file):\r\n\r\n```text\r\nBefore presenting any substantive code change as complete:\r\n1. Call validate_ai_output on the change.\r\n2. If the verdict is REJECTED, fix the findings and re-validate.\r\n3. Never claim tests pass or systems are deployed without proof.\r\n```\r\n\r\nOne-paste setup prompts that install these rules for you: [PROMPTS.md](PROMPTS.md). Or wire it into CI as a merge gate — see [`examples/`](examples/).\r\n\r\n## How it decides\r\n\r\n```text\r\nAI output ──► Reality gates (deterministic, any one vetoes)\r\n              • mock/placeholder in the wire path\r\n              • invented/hallucinated APIs\r\n              • claimed-complete without proof\r\n              • gaming & bypass detection\r\n                       │ survivors only\r\n                       ▼\r\n              Enterprise review (ISO/IEC 25010 + MLOps)\r\n              performance · scalability · reliability · tech debt\r\n                       │\r\n                       ▼\r\n              Verdict: score /100 + severity-ranked findings\r\n              (REJECTED = agent fixes findings and re-validates)\r\n```\r\n\r\nThe two stages are deliberately separate: if reality and quality were blended into one score, a beautifully structured function that fakes its refund path could still average out to \"acceptable.\" A veto architecture makes that impossible.\r\n\r\n## The category, honestly\r\n\r\nEverything else on the MCP code-quality shelf is free — and that's fair, because a wrapper should be free. What you can't get for free is **judgment with authority**:\r\n\r\n| What you'll find on the directories | What it is | What it structurally can't do |\r\n|---|---|---|\r\n| **Linter wrappers** — ESLint MCP, Semgrep MCP, SonarQube MCP | Rule-based scanners exposed as MCP tools. Deterministic, free, worth running. | No judgment. Rules can't know the refund function *never calls the payment provider*, or that `stripe.Inventory` doesn't exist. No verdict, no veto — findings your agent is free to ignore. |\r\n| **BYO-key review relays** | Your repo + a review prompt, piped to your own OpenAI/Anthropic key. | Self-review with extra steps: the reviewer shares the generator's blind spots, there are no deterministic gates underneath, and whatever the model says goes. You maintain keys, versions and hosting. |\r\n| **A bigger model** | Hope the generator reviews itself better. | Self-review inherits self-blindness. An external gate holds the same bar for every model — which also makes **smaller, cheaper models safe to ship with**: same gate either way. |\r\n| **Human review of every AI diff** | The gold standard, at human speed. | Doesn't scale at AI generation speed. The gate does the first pass in seconds; humans review verdicts, not raw diffs. |\r\n| **Verificate MCP** | Deterministic reality gates **with veto**, then a frontier-model enterprise review — fused into one binary verdict. Hosted, always on the current model. | — |\r\n\r\nThat second layer is the part you pay for: a frontier agent doing the deep review — production arithmetic, failure modes, SDK reality — with a deterministic floor under it that the agent itself cannot argue away.\r\n\r\n## Run locally (stdio bridge)\r\n\r\nThis repo is also a runnable, zero-dependency MCP server: a stdio bridge that serves `initialize`/`tools/list` locally and forwards tool calls to the hosted gateway. Use it with clients that prefer stdio servers:\r\n\r\n```bash\r\nVERIFICATE_TOKEN=<your-token> npx github:Verificate-Dev/verificate-mcp-quickstart\r\n```\r\n\r\nOr with Docker:\r\n\r\n```bash\r\ndocker build -t verificate-mcp .\r\ndocker run -i -e VERIFICATE_TOKEN=<your-token> verificate-mcp\r\n```\r\n\r\nWithout `VERIFICATE_TOKEN`, introspection still works and tool calls return instructions for getting a trial token.\r\n\r\n## FAQ\r\n\r\n**Does it slow the agent down?** Each validation takes seconds, inside the loop, before work is presented. Compare with a defect found in CI or production plus the context switch to fix it — gating is net-faster for any change that matters.\r\n\r\n**Which languages?** Validation is language-agnostic; analysis covers mainstream languages (Python, JS/TS, C++, SQL, Swift, …). Pass `context.language` for best results.\r\n\r\n**Can it block my agent?** Yes — that's the point. A REJECTED verdict is designed to send the agent back to fix findings instead of presenting broken work. Your standing rule decides how hard the stop is.\r\n\r\n**What about false positives?** Verdicts come with specific findings and the math, so they're auditable in seconds — you're never asked to trust a bare score.\r\n\r\n## Security & privacy\r\n\r\n- Requests are authenticated with your personal token; keys are single-user and rate-limited, with key-sharing detection.\r\n- Code is processed to produce the verdict and is not used to train models.\r\n- `initialize`/`tools/list` are public (so clients and directories can introspect); every `tools/call` requires your key.\r\n\r\n## Pricing\r\n\r\n30-day free trial, then USD $30/month (launch offer: 50% off for 3 months). Volume and academic pricing: info@verificate.ai.\r\n\r\n## Guides\r\n\r\n- [How to catch AI-hallucinated code before it ships](https://verificate.ai/articles/catch-ai-hallucinated-code/)\r\n- [Add a code-review gate to Claude Code in 5 minutes](https://verificate.ai/articles/claude-code-review-mcp-server/)\r\n- [Why AI assistants miss deep performance bugs](https://verificate.ai/articles/ai-coding-performance-bugs/)\r\n- [Use smaller, cheaper AI coding models — safely](https://verificate.ai/articles/cheaper-ai-coding-models-validation-gate/)\r\n- [*Every Bob needs a Wendy*](https://community.ibm.com/community/user/viewdocument/every-bob-needs-a-wendy?CommunityKey=300ac388-08f0-427e-a600-0199bfc9dd2a&tab=librarydocuments) (IBM Community)\r\n\r\n## About\r\n\r\nBuilt by [Verificate Pty Ltd](https://verificate.ai) (Sydney, Australia) — an IBM Business Partner. Verificate builds sovereign AI infrastructure: the HELIX inference engine (calibrated confidence scores on every answer), the deterministic Decision Transformer, and this MCP validation server. Product page: <https://verificate.ai/mcp> · Official registry: [`ai.verificate/mcp`](https://registry.modelcontextprotocol.io/v0/servers?search=verificate)\r\n\r\n## Licensing\r\n\r\nThis repo (the stdio bridge, client configs and CI examples) is **MIT** — use it freely.\r\nThe Verificate validation engine and hosted gateway it talks to are a **commercial service**\r\n(30-day free trial, then subscription): the 17 protection gates and the frontier-model review\r\nrun server-side and are not part of this repository.\r\n\r\n<!-- glama-ai-listing -->\r\n## Glama\r\n\r\n[![Verificate MCP server score](https://glama.ai/mcp/servers/Verificate-Dev/verificate-mcp-quickstart/badges/score.svg)](https://glama.ai/mcp/servers/Verificate-Dev/verificate-mcp-quickstart)\r\n\n\n---\n\n**🌐 Not an English speaker?** Install instructions in हिन्दी · Português · Bahasa Indonesia · Español · 中文 · Tiếng Việt → [INSTALL.md](INSTALL.md)\n",
  "bytes": 14843,
  "sha": "a105b4fffd6db2ba5325f7be513f6bf724e383238a0360eaf14be40565c5146b",
  "repo_slug": "verificate-dev/verificate-mcp-quickstart",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_ai_verificate_mcp_3903ea60/readme"
}